# Concepts

Axiad Mesh correlates accounts from every connected system into a single view
of who — and what — has access in your organization, then scores the risk each
one carries. The pages in this section explain the ideas the rest of the
documentation builds on:

- **[Identities](./identities.md)** — how Mesh correlates accounts from
  different systems into one identity, and how to review and correct
  correlations.
- **[Entities](./entities.md)** — how identities group into organizational
  entities so you can see risk by team, department, or function.
- **[Delegation](./delegation.md)** — how remediation work is assigned to the
  person best placed to act on it.
- **[Risk scoring](./risk-scoring.md)** — what the risk score means, how it is
  calculated, and how to read it across the product.
- **[Remediation](./remediation.md)** — how risks get fixed: guided steps in
  the product, delegation with direct user notifications, and automated
  external remediation through A2A agents.
- **[Programs](./programs.md)** — how Mesh tracks organization-wide security
  initiatives, such as a post-quantum migration or an MFA rollout, as
  measurable efforts with progress and loss exposure prevented.
- **[Policies](./policies.md)** — the rules Mesh evaluates your identities and
  assets against, including the cryptographic policies behind post-quantum
  readiness.
- **[Investigations](./investigations.md)** — how you drill from a summary into
  the evidence, and the identity graph and attack-path views you explore along
  the way.

One more mental model lives in the User Guide:
[Generative UI](../user-guide/generative-ui.md) explains **workspaces** — the
agent-composed views that exist alongside the classic dashboards these
concepts describe. The concepts on this page apply identically in both modes.

If you are setting up Mesh for the first time, start with
[Getting Started](/docs/getting-started) — it links back here whenever a step
introduces one of these ideas.
